Skip to content

Exposing secret on the client side is bad practice #54

@fniewijk

Description

@fniewijk

I was looking at using your package, but when I read your code and compare it with the manual it says that you should not share the app_secret client side. It suggests you should use the client side implicit authentication. link

Are you aware of this? This looks like an issue that is resolvable. The implicit authentication does not need the secret.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions